Validating controls
Validating the controls put in place is a very important task and one that must not be overlooked. Enforcing some form of validation program to ensure the controls you documented as part of your policies and baselines are enforced will help provide additional certainty and peace of mind. Having a second set of eyes to review anything you implement in the IT and security fields is always a good idea. This doesn't necessarily mean an incident will never happen, but it does show that you are executing due diligence and doing what is right.
In addition, it's important to validate that the vendors you partner with also maintain the same level of detail in protecting their environment as you do. The more we move data to vendor-managed cloud and SaaS services, the more due diligence is needed regarding making sure auditing access and validating controls are also in place in the vendor's environment. This is changing the dynamic of how we work in IT and...